Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 11.10, 11.04, 10.10, 10.04 LTS High: Firefox XSS and DoS

ubuntu
Calendar Grey March 16, 2012
Scroller Ubuntu
Numerous Firefox vulnerabilities resolved in Ubuntu update USN-1400-1 bolster defenses against XSS and DoS threats, with patches now accessible.
Several security issues were fixed in Firefox.

Summary

Several security issues were fixed in Firefox.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Soroush Dalili discovered that Firefox did not adequately protect against

dropping JavaScript links onto a frame. A remote attacker could, through

cross-site scripting (XSS), exploit this to modify the contents or steal

confidential data. (CVE-2012-0455)

Atte Kettunen discovered a use-after-free vulnerability in Firefox's

handling of SVG animations. An attacker could potentially exploit this to

execute arbitrary code with the privileges of the user invoking Firefox.

(CVE-2012-0457)

Atte Kettunen discovered an out of bounds read vulnerability in Firefox's

handling of SVG Filters. An attacker could potentially exploit this to make

data from the user's memory accessible to the page content. (CVE-2012-0456)

Mike Brooks discovered that using carriage return line feed (CRLF)

injection, one could introduce a new Content Security Policy (CSP)...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  firefox                         11.0+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
  firefox                         11.0+build1-0ubuntu0.11.04.1

Ubuntu 10.10:
  firefox                         11.0+build1-0ubuntu0.10.10.2

Ubuntu 10.04 LTS:
  firefox                         11.0+build1-0ubuntu0.10.04.2

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1400-1

CVE-2012-0451, CVE-2012-0455, CVE-2012-0457, CVE-2012-0458,

CVE-2012-0459, CVE-2012-0460, CVE-2012-0461, CVE-2012-0462,

CVE-2012-0464, https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/951250

Severity
important
Lowest
Low
Medium
High
Critical

March 16, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.